wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

last22

Total questions: 22

Worksheet time: 11mins

Name
Class
Date
1.

HIDS differs from NIDS in what manner?

a)

One is "high" IDS and the other is "normal"

b)

One is "host" IDS and the other is "normal"

c)

One is "homogeneous" IDS and the other is "network"

d)

They are the same thing

e)

None of the above

2.

The biggest challenge to signature-based security for detecting malware is which of the following?

a)

Difficulty in keeping the lists readable

b)

Difficulty in managing more than one list

c)

Behavioral anomalies

d)

Variants

e)

All of the above

3.

Which of the following is a false statement regarding SIEMs?

a)

A SIEM will not work with proper crypto

b)

SIEM security requires network tunnels

c)

SIEMS always require SOCs

d)

SOCs typically use SIEMS

e)

All the above

4.

Which of the following is a true statement?

a)

Perimeter protection works great on enterprise networks

b)

Perimeter protection works poorly on enterprise networks

c)

Perimeters work unless mobility is present

d)

Cloud requires perimeter protection

e)

All of the above

5.

Automation in a SOC is a good idea for which of the following?

a)

It is a mandatory requirement in most compliance frameworks

b)

It requires 24 by 7 operation

c)

It is already done in other parts of the enterprise

d)

It reduces response cycle times

e)

None of the above

6.

Which of the following is a true statement?

a)

IDS = IPS

b)

SIEM = SOC

c)

IDS is implied by IPS

d)

SOC is implied by SIEM

e)

All of the above

7.

The malicious client is sending a massive flood of SYN packets to the web server. Which of the following security mitigations choices (or none) is best for the web server administrator to employ to reduce the risk of this attack:

a)

Increased application-level authentication of the client

b)

Running a scan on the web server for vulnerabilities

c)

Implementing improved auditing on both the client and server

d)

None of the above.

8.

The malicious client is sniffing packets on the local LAN to detect any local activity of interest. Which of the following security mitigations would be best for the administrator of the local LAN to employ to reduce the risk of the malicious client inappropriately obtaining information from other LAN users:

a)

Warnings to users to be careful

b)

LAN encryption

c)

Physical security of LAN equipment

d)

None of the above

9.

The malicious client is sending a massive number of spoofed packets to the web server, resulting in response SYN/ACK packets being sent to the spoofed address, perhaps causing a flood condition for that system. Which of the following security mitigations would be best employed on the web server to deal with the massive number of spoofed packets:

a)

Running an IPS in front of the server to shun the spoofed source

b)

Running a DOS defense service in front of the web server that detects the flood of spoofed sources

c)

Notifying the spoofed IP address of the incident

d)

All of the above

10.

The malicious client is repeatedly trying to use administrative commands to log into the web server. Which of the following security mitigations would be best for the:

a)

Positioning a firewall in front of the server to filter commands

b)

Improving the strength of administrative passwords

c)

Running an IDS in front of the server to detect attacks

d)

All of the above

11.

The malicious client is using a powerful scanning tool to launch scans against the web server. Which of the following security mitigations would be best for the administrator of the web server employ to reduce the risk of the scan:

a)

Minimizing the inbound network capacity

b)

Minimizing the inbound services

c)

Maximizing encryption on all ports

d)

None of the above

12.

The malicious client recruits a botnet and launches a massive DDOS attack using a target DNS server that is sent requests spoofed as coming from the web server. Which of the following security mitigations would be best for the DNS administrator to consider using to reduce the risk of this attack:

a)

Do not respond to the DNS requests

b)

Demand that tunneling protocols be used for all DNS requests

c)

Turn on auditing so that records of attacks are available

d)

None of the above.

13.

Perimeters exhibit which of the following weaknesses?

a)

Clash between management and audit

b)

Weak performance

c)

Too many rules

d)

Too few policy controls

e)

All of the above

14.

Advanced persistent threats (APTs) exfiltrate data through which of the following weaknesses?

a)

Open gateway access to the Web

b)

Open remote access into the LAN

c)

Open source software reviews

d)

Hacking conference discussions

e)

None of the above

15.

Third party security is best accomplished through which of the following?

a)

Contracts

b)

Service level agreements

c)

Monitoring

d)

Vetting

e)

All of the above

16.

DDOS attacks at layer 3 are characterized by which of the following?

a)

Weak encryption

b)

Volume

c)

Efficiency of payload

d)

Tagged labels

e)

All of the above

17.

Which of the following techniques reduce DDOS risk?

a)

Protocol redesign

b)

Network traffic obscuring

c)

Network traffic redirection

d)

All of the above

18.

Which is the following is a true statement?

a)

DDOS targets spoofed targets

b)

DDOS never involves spoofed sources

c)

DDOS might involve spoofed targets

d)

DDOS might involve spoofed sources

e)

All of the above

19.

Third party attacks are tough to mitigate for which of the following reasons?

a)

Attacks are distributed

b)

Attacks are centralized

c)

Attacks are based on vulnerabilities

d)

Vulnerabilities are tough to manage remotely

e)

All of the above

20.

APTs are best mitigated through which of the following techniques?

a)

Architectural improvement

b)

Policy improvement

c)

Procedural improvement

d)

All of the above

21.

Perimeter security exhibits which of the following?

a)

Standards-based protection

b)

Effective mitigation of insiders

c)

Good protection against APT

d)

None of the above

22.

Which of the following is not a true statement?

a)

DDOS attacks will increasingly involve cloud

b)

DDOS attacks will increasingly involve mobility

c)

DDOS attacks will grow in an unbounded manner

d)

DDOS attacks will increasingly involve IoT

e)

None of the above